Cyber Security

What is Cyber Security

Listen to Article

The digital world is continually changing, and cyber security has become a concern for individuals, businesses and governments alike.
The purpose of cyber security is to ward off data breaches, provide a safe environment in the case of hardware failure and to protect information from ransom attacks from criminals, who can make your data inaccessible unless a ransom payment is agreed, normally using cryptocurrency. Individuals who can gain such unauthorized access to the data on your computer system or computers networks can range from hackers who write scripts to try to compromise cyber security or organised criminal enterprises who will carry out technically advanced attacks, purely for illegal financial gain.

Security Planning

Businesses rely on Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) for their security planning. It is essential that everyone takes cyber security seriously as ignoring this growing problem will eventually result in an IT disaster. Today, it forms an indispensable part of the risk management strategy for any organisation.

Cyber Security applies to all, whether for an individual who should ensure that software updates and virus protection is kept up to date, without fail, to large organisations, who rely on specialists within the organisation to ensure their IT infrastructure is fully protected with suitable planning in place, to recover from data breaches. IT is continually changing and becoming more advanced and complex, so higher level management ensure the security protection is in place, and that staff within the organisation are fully aware of the online risks.

No software is bug-free, and this poses a further risk. Bugs in software can potentially create security issues, and this is the reason why companies such as Microsoft are continually releasing updates for their products such as Windows and Word. These updates may include bug fixes but typically will be addressing security risks that may have been identified.

Cyber Security Training

In this digital age, the IT users are often the cause of cyber security issues. Each user has a different purpose when using a computer. While some have better knowledge about computer security, many don’t. It is essential that each user understands the cyber security risks, and how they can work to minimise the risk of a security breach.
Some approaches that assist the cyber security planning and programmes are as follows:

Software developers need to not only be able to develop software, but they should code in an approach that does not allow easy access to potential hackers. Any software developed should also be a PEN (Penetration) tested, this is a key element of cyber security, identify to developers security flaws within the software.

Training individuals to understand how to ensure best security at all times, such as ensuring business software and virus protection has the latest updates applied.

Training end users to be able to identify emails that are phishing or to not open attachments from unknown sources or social media.

Cyber Attacks

No business can be 100% protected from cyber attacks, regardless of the commitment each organisation has to cyber security. However, cyber-attacks typically will occur through the most vulnerable point of access. These weak points are often easy to secure, and if businesses follow basic cyber security protocol, the risk can be minimised a great deal. These simple security procedures which are also known as cyber hygiene include elements such as.

These are just the basics. It is necessary for businesses to extend these practices much further to maximise their cyber security, as experienced hackers will find any weaknesses that may exist. With technology continuing to advance, the security risks are now expanding beyond computers in business, and at homes, there are now so many physical systems that can be hacked, including:

Automotive systems

Airlines systems

Internet-enabled electronic devices

Automated systems such as traffic lights in a busy city

The Internet of Things (IoT), also brings new challenges for cyber security. With more and more reliance on these systems, cybersecurity has never been more critical. New regulations, such as the GDPR, is adding further complications to cybersecurity. The GDPR, for example, has a clear security policy, with large GDPR fines for non-compliance. With cyber attacks becoming more frequent and destructive, resulting in potentially huge financial losses for businesses as well as their credibility, businesses are looking to experience cyber security professionals to ensure their organisations are fully protected.

Finding suitably experienced professionals has become a difficult task, with the sudden rise in cyber attacks, there is now a distinct shortage of suitable candidates for these high-end security roles.

The key elements of cybersecurity

The definition of cybersecurity needs to be understood more granularly. Businesses with cybersecurity strategies need to ensure that each of the subcategories is considered, overlooking any, potentially will leave organisations vulnerable.

Critical infrastructure

Communities rely on critical infrastructure for their day to day existence. These systems include hospitals, utility companies such as electric, gas or water, and automated systems used throughout cities such as traffic lights and railway crossings for example.

These critical infrastructure systems are connected to the Internet, and anything connected to the internet is at risk of a cyber attack. The organisations that manage the critical infrastructure must ensure the highest level of planning for cybersecurity, and continually re-evaluate their planning, contingency plans, and risk analysis/prevention is an ongoing process.

Networks

Protection of data and information on a network within an organisation can be controlled with different levels of login/user access. Such a move limits the access for individuals within an organisation and for malicious users from outside the organisation that may have gained access.

There are specialised tools that monitor traffic on a network; these tools will also highlight potential risks. The issue with these tools, however, they are continually generating data. Due to the thousands of logs that are created, it is possible that genuine alerts are missed in the process. With the continued advancement of Artificial Intelligence (AI) and machine learning, security software can identify and alert of imminent risks.

Cloud security

More organisations are storing and sharing data on the Cloud, such as:

GSuite for emails, storage, and productivity

DropBox and One Drive for storage

Xero for accounts

Office365 for productivity

This creates further issues with regard to cybersecurity and also for new regulations like the GDPR. Poorly configured cloud solutions can result in cyber attacks, and it introduces a substantial risk. Cybersecurity is no longer under the control of your organisation. Businesses are relying on others to implement cyber security strategies. Organisations should carefully consider individual cloud solutions before taking the leap, perform due diligence to ensure these vendors also take cyber security seriously.

Applications

The most vulnerable area for cybersecurity is web applications. With developers worldwide creating web applications, each development team has a different skill set and coding standards. Often developers have not developed the systems with secure coding practices, leaving these systems vulnerable and prone to attack.

Web applications should be tested for security weaknesses by performing Penetration (PEN) testing. Software such as OWASP or Fortify will identify issues within web applications that can be addressed by the developers. PEN testing is not a one-off procedure; the process should be repeated at regular intervals as new hacking techniques become known, ensure software is always secure.

Internet of Things (IoT)

This can be related to any system that can be accessed via the Internet, such as automated lighting and heating at home, fitness apps tracking your daily actions or a speed sensor in a motor vehicle for an insurance company.
IoT systems are installed, and the software or security updates are ignored. Such behaviour can risk the privacy of the users of the IoT systems and also others as often the IoT systems are part of a botnet.

What are the different types of cyber threats?

Cybersecurity is essential to protect against the three most common types of cyber attacks, as listed below.

Confidentiality – this type of cyber attack is simply about gaining access to IT equipment to obtain personal information from an individual or a business. The information obtained can be used for credit card fraud or identity theft to allow other documents such as passports to be produced. Certain countries may also use this approach to obtain personal information from governments for example.

Integrity or Sabotage – this form of cyber threat aims to destroy or corrupt information within online systems, making the systems unusable for the individuals or businesses that rely on them. This type of attack can vary in size from just a minor corruption of data or substantial damage when criminals are typically looking to benefit from this type of cyber attack.

Availability: Ransomware is becoming a major problem by making systems unavailable to users by encrypting files. Unless a proper recovery plan is in place by the cybersecurity team, often the only way to regain access to the encrypted systems is by making a ransom payment, typically with untraceable cryptocurrency. DDOS (Distributed Denial of Service) attacks are common by forcing large volumes of data across a network to make it inaccessible.

How are cyberattacks carried out?

Social Engineering – this approach is one of the oldest approaches used by criminals to gain access to valuable information. Viruses such as Trojan Horses may exist on certain websites, either intentionally or unknown to the website owner.
Visitors to the web site may open files, and this leads to the virus being downloaded to their equipment allow the virus to gain access to personal information.
Although cybersecurity can help to protect against this type of access, the best form of protection is the education of the users. Accessing only trusted sites and to carefully consider files that are downloaded, are key considerations.

Phishing – one of the most common approaches to gain useful and personal information is by phishing. A genuine email may be received from what appears to be your bank, for example, requesting you to login to your bank account. Information such as your username and password is then captured and re-used to gain access to your accounts. To avoid falling prey to phishing attacks, two-factor authentication (2FA) is recommended, when logging into bank accounts for example, as not only is it necessary to log in to the website, but also a second authentication can be sent to your mobile phone ensuring additional protection.

Out of date software – software developers take cybersecurity seriously, and new updates are regularly released to not only fix bugs but also to ensure that their software continues to be as secure as possible against cybersecurity attacks. It is critical that the software updates are installed by businesses, as software not kept up to date is more at risk of a cyber attack.

Cybersecurity careers

Finding the best team possible to manage your organisation’s cybersecurity strategy is a difficult task. In fact, with stringent laws like GDPR taking effect in the European Union, the demand for cybersecurity resources is at its highest, and there is certainly a skill shortage.
Protecting organisations data and infrastructure has never been more important, with a cybersecurity team now requiring different skills from

Security Engineer

Information Security Officer

Data Protection Officer

Penetration Testers

Dedicated cyber security teams are now paramount and are in high demand with organisations ready to pay them hefty packages. The era has passed when cybersecurity may have been one of the tasks of one of the technical engineers. The cybersecurity roles are now specialist.
Cybersecurity is a 24/7/365 procedure, working around the clock to ensure internal systems are well protected and when a potential attack is identified, reacting quickly to rectify the attack. A rapidly changing environment that relies on a proactive team to continually protect the businesses interests.

The following are key roles in the cybersecurity team.

Chief Information Security Officer (CISO)

This is the lead role in the cybersecurity team; the CISO oversees the cyber security department. The CISO defines the organisation’s security policies and procedures and ensures that all security planning in place protects the organisation in the case of a cyber attack.

✓ Cyber Security Analyst

The Cyber Security Analyst has a number of key responsibilities within an organisation.

Ensure that there is a security plan in place that has been fully tested. The plan should continue to be updated and evolve.

Protection of data and files held within the organisation, ensuring that only the appropriate individuals can have access to these files.

Monitor access, identifying any potential security breaches. Security breaches should be analysed to identify the vulnerability and rectified.

Ongoing security audits both internally and externally. Appropriate network systems should be in place to prevent attacks. In the case of an intrusion, network tools should detect these intrusions and follow an incident response protocol.

Define and manage the organisation’s corporate security policy.

✓ Security Architect

The Security Architect sits in between the management and the technical team. Their role is to ensure the organisation’s network and security infrastructure is configured to meet the businesses cybersecurity requirements. The Security Architect must have an excellent understanding of the businesses and technology to ensure that the solution implemented is the correct solution.

✓ Security Engineer

This role within the cybersecurity team requires the Security Engineer to be at the forefront of the organisation. The individual need to be able to communicate well throughout the business and have excellent technical skills to fulfil this role.

The key purpose of this role is to ensure that the infrastructure, network, and data centres are fully secure and to develop and evolve strategies that continue to protect the organisation’s infrastructure.